#%PAM-1.0
auth            requisite       pam_nologin.so
auth            required        pam_env.so

auth            required        pam_permit.so

auth            sufficient      pam_succeed_if.so uid >= 1000 quiet
auth            required        pam_deny.so

account         required        pam_access.so
account         required        pam_time.so
account         required        pam_unix.so

password        required        pam_unix.so
password        required        pam_deny.so

session         required        pam_limits.so
session         required        pam_unix.so

session         required        pam_loginuid.so
-session        optional        pam_systemd.so

session         optional        pam_keyinit.so revoke
session         required        pam_limits.so
session         required        pam_unix.so
